IT Audit · Technology Assurance · AI Assurance · South Africa

Assurance you can prove.

Resilitech gives regulated South African enterprises independent IT audit and technology assurance: evidence-led, framework-mapped, and board-ready. Less alarm, more certainty.

ISO 27001-aligned practiceTrusted by regulated enterprises across finance, healthcare & the public sector.
Aligned to the frameworks your regulators expect
POPIAKing IVISO 27001PCI DSSSOC 2NIST CSFCOBITCIS Controls v8.1
What we do

Technology assurance, end to end

From IT audit and SAP controls to AI assurance and continuous monitoring, we verify whether your controls hold, show you where they don’t, and hand you the evidence.

Pillar 01

IT Audit & Technology Assurance

Independent, evidence-based verification that your governance, controls and third parties do what your policies claim.

  • IT audit & IT general controls (ITGCs)Design and operating-effectiveness testing across your control environment.
  • Application controls & SAP assuranceSAP Basis, SAP GRC and configurable controls across FI, MM and HCM.
  • IT governance & King IV / COBIT advisoryBoard and committee reporting that stands up to scrutiny.
  • Continuous auditing & monitoringEarlier risk identification through automated, data-driven testing.
  • Data analytics & automationACL, IDEA, SQL and RPA to test whole populations, not samples.
Pillar 02

Cybersecurity & AI Assurance

Independent assurance over your cybersecurity and AI controls, and the specific, prioritised steps to close real exposure.

  • Cybersecurity assuranceReviews against CIS Critical Security Controls v8.1 and CIS Benchmarks.
  • AI governance & AI assuranceAssess AI governance, emerging risks and control effectiveness.
  • ISO 27001 readiness & certification supportGap analysis, ISMS build-out and audit preparation.
  • Third-party & vendor risk assuranceDue diligence and continuous supplier monitoring.
  • Penetration testing & vulnerability managementObjective-led testing with tracked, verified remediation.
Why Resilitech

Assurance built on evidence, not adjectives

Independent & evidence-led

Every finding is traceable to evidence and mapped to a control. No scare tactics, just what’s true, and what to do about it.

Locally rooted, POPIA-fluent

A South African team that knows the Regulator, King IV and the realities of operating here, not a template flown in from abroad.

Board-ready reporting

Findings your executives and auditors can both read: technical depth underneath, clear posture and risk on top.

Continuous, not point-in-time

Posture drifts between audits. We monitor continuously so the annual report is a confirmation, never a surprise.

Track record

Depth you can rely on

14+
Years leading IT audit & technology risk
8
Sectors served, from banking to the public sector
Full
Coverage: IT, SAP, cyber & AI assurance
24/7
Continuous monitoring for retained clients
Proof & perspective

Case study & latest insights

Resilitech assurance team reviewing a client's security and compliance dashboards
Financial services · Case study

How a JSE-listed insurer cut critical exposure by 71%

A continuous vulnerability-management programme plus quarterly assurance took a fragmented estate to a defensible, board-reported posture in three quarters.

71%
Fewer critical findings
3
Frameworks mapped
9mo
To defensible posture
From the Founder
Ayanda Kunene, Founder and Managing Director of Resilitech
I started Resilitech because South African boards were being handed fear, not facts. Good assurance lowers anxiety. It tells you exactly where you stand, backs it with evidence, and shows you the shortest path to resilience. That quiet confidence is the whole point.
AK
Ayanda Kunene
Founder & Managing Director, Resilitech

Ready to see exactly where you stand?

Request a baseline assessment. In two weeks you’ll have a board-ready view of your posture, mapped to the frameworks that matter to your regulators.